Command Injection Vulnerability in Tenda M3 Router
CVE-2022-26290
9.8CRITICAL
What is CVE-2022-26290?
The Tenda M3 router version 1.10 V1.0.0.12(4856) is impacted by a command injection vulnerability in the /goform/WriteFacMac component. This flaw allows an attacker to execute arbitrary commands on the device, potentially leading to unauthorized access and control over the router's functionality. It is critical for users to apply security patches and updates to mitigate the risks associated with this vulnerability.